No. Apple can't guarantee their software is secure, so their walled garden doesn't guarantee anything like what you say.
A while back Apple started pulling anti-virus apps from the app store presumably because they aren't needed: https://9to5mac.com/2015/03/19/apple-app-store-antivirus/. For contrast here is Microsoft's official article on protecting your PC from viruses: https://support.microsoft.com/en-us/help/17228/windows-prote...
In addition, about 80% of iPhones in use are running the latest version of iOS. Apple can patch exploits and have the majority of iPhones secured in a short amount of time. iOS is unique in that respect, and that is just one mitigating factor that makes iOS malware very implausible.
> A while back Apple started pulling anti-virus apps from the app store presumably because they aren't needed.
I think you presume too much. An effective antivirus program cannot run in a sandbox that isolates it from other processes. If Apple pulled 3rd party antivirus apps, I bet it was because they could not both work as advertised and simultaneously obey the sandbox, not because they "aren't needed" (presumably because the platform is "secure").
As for your original statement:
>> You can't get viruses on iOS unless you're jailbroken - Apple's walled garden pretty much guarantees that.
Here's a counterexample: https://www.kaspersky.com/blog/pegasus-spyware/14604/
Governments don't have special hacking powers, they mainly have money and manpower.
It's true, iOS might raise the bar a little bit compared to some other systems, but IMHO it's misleading and dangerous to claim that it's invulnerable.
Again, no. Here's another counterexample (which is recent and appears to have been active on the App Store for ~1yr):
https://researchcenter.paloaltonetworks.com/2016/03/acedecei...
"These malicious iOS apps provide a connection to a third party app store controlled by the author for user to download iOS apps or games. It encourages users to input their Apple IDs and passwords for more features, and provided these credentials will be uploaded to AceDeceiver’s C2 server after being encrypted."
That's not state actor stuff.
However, I shouldn't have to keep providing counterexamples to convince you of your absurd claims of practical invulnerability. Apple has not made any kind of security quantum leap: no one has. Apple's systems are vulnerable to the same types of flaws, by the same types of attackers, as any other system in wide use. The main difference is that Apple has restricted their platform to the extent they have an easier time implementing security best practices. iOS is still vulnerable to flaws Apple doesn't know about or hasn't patched, and those flaws can be exploited for as long as Apple remains unaware or fails to act. That's not fundamentally different position from Microsoft, Google, or any other similar company.
There have been a handful of cases of iOS malware over the years, but no serious exploit has been widespread. For an exhaustive list see here: https://www.theiphonewiki.com/wiki/Malware_for_iOS
The most wide spread malicious apps are generally apps that access private apis but manage to get through Apple's review process and onto the App Store. They can be far reaching but again they can't breach the sandbox which means the absolute worst thing they do is upload your email address to some server or try to trick you into giving away your password. I still stand by my assertion that the average user doesn't need to worry about malware on iOS.
False, they can breach the sandbox. The sandbox is software and it has exploitable flaws until proven otherwise (which hasn't happened).
Look, like I said in another comment: you'd be fine if you restricted yourself to relative comparisons, but for some reason you have to go too far and make absolute statements of security, statements which can't possibly be true. iOS might be more secure than other OSes, but it's still insecure, and it's dangerous and misleading to say that any users don't need to exercise reasonable caution.
So the point is that you aren't going to get malware on your small, entirely contrained and locked down portable computing device like you are on your larger, general purpose open computing device? Why even bother making that comparison?
OS X has plenty of vulnerabilities.[1] If you want to make a coherent argument, source your claims that modern windows only requires you visit a site or open an email, and we can look to see if Apple has had similar vulnerabilities in equivalent products.
1: https://www.cvedetails.com/vulnerability-list/vendor_id-49/p...
Probably true on almost every OS.
I've never seen nor heard of any actual malware outbreak from a non-jailbroken app.
So, every apps seems to be an attack sureface.
The only jailbreak for iOS 10 was semi-teathered and only made public after Apple had patched the vulnerabilities. In order for this to work as malware the user would have to open the malicious app every time their phone restarts. Not only that, every time the they open the app their phone would appear to be out of storage and then promptly crash to the boot screen. It would be a bit of a hard sell.
Apple/etc seem to be suck in the mindset of the various antivirus products before the advent of adaware/etc. So the products aren't strictly virus/trojans/worms/etc but they definitely fit the definition of malware and the end results are potentially just as bad. I would actually prefer any number of virus's over the some of the shenanigans the facebook app has been accused of.
With iOS, that pattern is a lot harder to abuse, and with enforced sandboxing, side-effects between programs (or, 'apps') are somewhat non-existent.
Most of the things that make non-Windows systems less infected seem to either be due to a better security design, less casual users or a drastically lower market share making it a smaller target with possible less effective organic spreading of malware. (or possibly a combination of the three)
What's the point of your critique when you can apply it to literally any piece of software? Even SEL4 relies on a correct processor, and yours has flaws.
I switched to Macs back in 2007. I work in IT, have always been careful to install anti virus software on Windows machines and showed my family how to avoid click bait and dangerous downloads. Even so I frequently used to have to clean malware off my old Windows machines. We do have one windows laptop on Windows 7 which is lightly used and most recently it got infected with a Firefox toolbar extension thing a few years ago that took a week to get rid of completely.
I have never once since 2007 had to deal with a single piece of malware on any of our Macs. I know it exists, Handbrake downloads got infected a while back, but the difference is night and day. In my experience Mac OS is dramatically safer than even a fully up to date Windows machine with top tier virus protection software installed.
Maybe that's changed with recent versions of Windows. Cool. Actually the only thing that drives me potty about Macs is the keychain getting corrupted, drives me potty.
Why would the black market pay huge sums for a sandbox escape or jailbreak -- unless it's for malware?
If the answer is "for use by intelligence agencies", well that's malware by any reasonable definition.
Chromebooks are probably the single best option for a computer with a keyboard. I wish the chrometops were a bit more compelling, as I'd probably switch my other grandmother (ubuntu 16.04) over. She has one program she plays a lot (since 1996) which runs under WINE.
Because those apps shouldn't be able to be opened unless the author has code signed them.
In which case if they are malware then just report it to Apple and they can centrally block the app.